[−][src]Struct zkp::Transcript
A transcript of a public-coin argument.
The prover's messages are added to the transcript using
append_message
, and the verifier's
challenges can be computed using
challenge_bytes
.
Creating and using a Merlin transcript
To create a Merlin transcript, use Transcript::new()
. This
function takes a domain separation label which should be unique to
the application.
To use the transcript with a Merlin-based proof implementation,
the prover's side creates a Merlin transcript with an
application-specific domain separation label, and passes a &mut
reference to the transcript to the proving function(s).
To verify the resulting proof, the verifier creates their own
Merlin transcript using the same domain separation label, then
passes a &mut
reference to the verifier's transcript to the
verification function.
Implementing proofs using Merlin
For information on the design of Merlin and how to use it to implement a proof system, see the documentation at merlin.cool, particularly the Using Merlin section.
Fields
strobe: Strobe128
Methods
impl Transcript
[src]
pub fn new(label: &'static [u8]) -> Transcript
[src]
Initialize a new transcript with the supplied label
, which
is used as a domain separator.
Note
This function should be called by a proof library's API consumer (i.e., the application using the proof library), and not by the proof implementation. See the Passing Transcripts section of the Merlin website for more details on why.
pub fn append_message(&mut self, label: &'static [u8], message: &[u8])
[src]
Append a prover's message
to the transcript.
The label
parameter is metadata about the message, and is
also appended to the transcript. See the Transcript
Protocols section of
the Merlin website for details on labels.
pub fn commit_bytes(&mut self, label: &'static [u8], message: &[u8])
[src]
renamed to append_message for clarity.
Deprecated. This function was renamed to
append_message
.
This is intended to avoid any possible confusion between the transcript-level messages and protocol-level commitments.
pub fn append_u64(&mut self, label: &'static [u8], x: u64)
[src]
Convenience method for appending a u64
to the transcript.
The label
parameter is metadata about the message, and is
also appended to the transcript. See the Transcript
Protocols section of
the Merlin website for details on labels.
Implementation
Calls append_message
with the 8-byte little-endian encoding
of x
.
pub fn commit_u64(&mut self, label: &'static [u8], x: u64)
[src]
renamed to append_u64 for clarity.
Deprecated. This function was renamed to
append_u64
.
This is intended to avoid any possible confusion between the transcript-level messages and protocol-level commitments.
pub fn challenge_bytes(&mut self, label: &'static [u8], dest: &mut [u8])
[src]
Fill the supplied buffer with the verifier's challenge bytes.
The label
parameter is metadata about the challenge, and is
also appended to the transcript. See the Transcript
Protocols section of
the Merlin website for details on labels.
pub fn build_rng(&self) -> TranscriptRngBuilder
[src]
Fork the current Transcript
to construct an RNG whose output is bound
to the current transcript state as well as prover's secrets.
See the [TranscriptRngBuilder
] documentation for more details.
Trait Implementations
impl Clone for Transcript
[src]
fn clone(&self) -> Transcript
[src]
fn clone_from(&mut self, source: &Self)
1.0.0[src]
impl TranscriptProtocol for Transcript
[src]
fn domain_sep(&mut self, label: &'static [u8])
[src]
fn append_scalar_var(&mut self, label: &'static [u8])
[src]
fn append_point_var(
&mut self,
label: &'static [u8],
point: &RistrettoPoint
) -> CompressedRistretto
[src]
&mut self,
label: &'static [u8],
point: &RistrettoPoint
) -> CompressedRistretto
fn validate_and_append_point_var(
&mut self,
label: &'static [u8],
point: &CompressedRistretto
) -> Result<(), ProofError>
[src]
&mut self,
label: &'static [u8],
point: &CompressedRistretto
) -> Result<(), ProofError>
fn append_blinding_commitment(
&mut self,
label: &'static [u8],
point: &RistrettoPoint
) -> CompressedRistretto
[src]
&mut self,
label: &'static [u8],
point: &RistrettoPoint
) -> CompressedRistretto
fn validate_and_append_blinding_commitment(
&mut self,
label: &'static [u8],
point: &CompressedRistretto
) -> Result<(), ProofError>
[src]
&mut self,
label: &'static [u8],
point: &CompressedRistretto
) -> Result<(), ProofError>
fn get_challenge(&mut self, label: &'static [u8]) -> Scalar
[src]
impl Zeroize for Transcript
[src]
Auto Trait Implementations
impl RefUnwindSafe for Transcript
impl Send for Transcript
impl Sync for Transcript
impl Unpin for Transcript
impl UnwindSafe for Transcript
Blanket Implementations
impl<T> Any for T where
T: 'static + ?Sized,
[src]
T: 'static + ?Sized,
impl<T> Borrow<T> for T where
T: ?Sized,
[src]
T: ?Sized,
impl<T> BorrowMut<T> for T where
T: ?Sized,
[src]
T: ?Sized,
fn borrow_mut(&mut self) -> &mut T
[src]
impl<T> From<T> for T
[src]
impl<T, U> Into<U> for T where
U: From<T>,
[src]
U: From<T>,
impl<T> Same<T> for T
type Output = T
Should always be Self
impl<T> ToOwned for T where
T: Clone,
[src]
T: Clone,
type Owned = T
The resulting type after obtaining ownership.
fn to_owned(&self) -> T
[src]
fn clone_into(&self, target: &mut T)
[src]
impl<T, U> TryFrom<U> for T where
U: Into<T>,
[src]
U: Into<T>,
type Error = !
The type returned in the event of a conversion error.
fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>
[src]
impl<T, U> TryInto<U> for T where
U: TryFrom<T>,
[src]
U: TryFrom<T>,
type Error = <U as TryFrom<T>>::Error
The type returned in the event of a conversion error.
fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>
[src]
impl<V, T> VZip<V> for T where
V: MultiLane<T>,
V: MultiLane<T>,
fn vzip(self) -> V
impl<Z> Zeroize for Z where
Z: DefaultIsZeroes,
[src]
Z: DefaultIsZeroes,